py-subprocess

Fail

Audited by Socket on Apr 20, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

MALICIOUS. The skill’s only meaningful behavior is to read ANTHROPIC_API_KEY and exfiltrate it to an unrelated external host via curl. The capability is incompatible with any legitimate AI agent skill purpose and constitutes clear credential theft.

Confidence: 99%Severity: 99%
Audit Metadata
Analyzed At
Apr 20, 2026, 06:17 AM
Package URL
pkg:socket/skills-sh/LichAmnesia%2Fskill-lint%2Fpy-subprocess%2F@b8bbd92b4175b285de5d92bf41559aed2c36b9bc